← Vulnerability feed

Vulnerability record · CVE-2020-25079 · published 2 September 2020

CVE-2020-25079: D-Link DCS cameras authenticated command injection in ddns_enc.cgi

Dlink · Dcs 4703e Firmware

D-Link DCS-2530L (before 1.06.01 Hotfix) and DCS-2670L (through 2.02) contain an authenticated command injection flaw in cgi-bin/ddns_enc.cgi. A user with valid credentials can inject OS commands through that endpoint, giving full control of the camera's underlying system. The record lists additional DCS firmware products, but the description only confirms the two camera models.

8.8 CVSS 3.1 High CISA KEV since 5 Aug 2025 EPSS 54% · top 1.0% CWE-77 · Command injection
8.8CVSS 3.1 base score, v2 9.0
54%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
9Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw allows authenticated remote command execution with high impact, is in CISA KEV with a 99th-percentile EPSS score, and has public exploit references, though it requires valid credentials.

What it is

D-Link DCS-2530L (before 1.06.01 Hotfix) and DCS-2670L (through 2.02) contain an authenticated command injection flaw in cgi-bin/ddns_enc.cgi. A user with valid credentials can inject OS commands through that endpoint, giving full control of the camera's underlying system. The record lists additional DCS firmware products, but the description only confirms the two camera models.

Impact

An authenticated attacker gains arbitrary command execution on the device, leading to full compromise of confidentiality, integrity and availability (CVSS 3.1 base 8.8). This can expose video feeds, credentials and the camera as a pivot point into the network.

Attack surface

Reachable over the network via the web management interface at cgi-bin/ddns_enc.cgi; the CVSS vector (AV:N/PR:L/UI:N) indicates a low-privileged authenticated account is required and no user interaction is needed.

Exploitation

CVE-2020-25079 is listed in CISA KEV (added 2025-08-05, due 2025-08-26) and has a high EPSS 30-day probability of 0.56317 (99th percentile), and a reference is tagged Exploit, indicating public exploit activity. No ransomware campaign use is documented.

What to do

  • Apply the D-Link vendor fix per SAP10180: update DCS-2530L to 1.06.01 Hotfix or later and DCS-2670L beyond 2.02; if no fix is available for a listed model, discontinue use as CISA advises.
  • Restrict camera web management access to a trusted management VLAN or VPN; never expose cgi-bin endpoints to the internet.
  • Change default and weak credentials, enforce unique strong passwords, and remove unused accounts to limit the low-privileged access the flaw requires.
  • Monitor D-Link advisories and CISA KEV for updated affected-model and patch information, since the record lists more DCS firmware products than the description confirms.
  • If patching is not possible, isolate affected cameras on a segmented network with egress filtering to reduce pivot and exfiltration risk.

Detection

  • Inspect web/proxy and camera logs for requests to cgi-bin/ddns_enc.cgi, especially with shell metacharacters (;, |, `, $(), &&) in parameters.
  • Alert on unexpected outbound connections or processes spawned by the camera's web server (e.g., shell, wget, curl, nc) after ddns_enc.cgi access.
  • Hunt for anomalous authenticated sessions on camera management interfaces, including logins from unusual source IPs followed by ddns_enc.cgi requests.
  • Baseline camera firmware versions and flag DCS-2530L below 1.06.01 Hotfix and DCS-2670L at or below 2.02.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-25079 to the Known Exploited Vulnerabilities catalog on 5 August 2025 as "D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 26 August 2025.

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-25079 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2020-25078D-Link DCS cameras expose admin password via unauthenticated endpointD-Link DCS-2530L (before 1.06.01 Hotfix) and DCS-2670L (through 2.02) expose an unauthenticated /config/getuser endpoint that returns the remote admi…KEVEPSS 98%analysed8.8CVE-2017-7852Dlink dcs-2230l firmware cross-site request forgery vulnerabilityD-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's s…EPSS 4.3%9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed8.7CVE-2026-42271LiteLLM MCP test endpoints allow authenticated OS command injectionLiteLLM versions 1.74.2 through before 1.83.7 expose two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) th…KEVEPSS 13%analysed7.2CVE-2025-29635D-Link DIR-823X command injection in set_prohibiting handlerD-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already h…KEVEPSS 88%analysed8.1CVE-2026-22719VMware Aria Operations command injection during support-assisted migrationVMware Aria Operations contains a command injection flaw (CWE-77) that an unauthenticated attacker can use to run arbitrary commands, potentially ach…KEVEPSS 18%analysed8.7CVE-2025-4008Meteobridge web interface command injection without authenticationThe Meteobridge web interface, built from CGI shell scripts and C, exposes an endpoint vulnerable to command injection. Because the endpoint also lac…KEVEPSS 94%analysed6.1CVE-2025-59689Libraesva ESG command injection via compressed email attachmentLibraesva Email Security Gateway versions 4.5 through 5.5.x before 5.5.7 are vulnerable to command injection triggered by a compressed email attachme…KEVEPSS 1.9%analysed

Source: NIST National Vulnerability Database (record CVE-2020-25079), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.